• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Facebook.com not working through 1 node of TMG array

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [Threat Management Gateway (TMG) 2010] >> General >> Facebook.com not working through 1 node of TMG array Page: [1]
Login
Message << Older Topic   Newer Topic >>
Facebook.com not working through 1 node of TMG array - 18.Jul.2012 8:45:12 AM   
cruachan

 

Posts: 4
Joined: 18.Jul.2012
Status: offline
Hey guys, long time reader of site/forum but first time poster.

We have an odd issue where TMG EE is setup in a 2-node array, and everything is fine through one node but the other does not receive any replies from facebook.com (Marketing dept use it, I'd block it if it was up to me!)

DNS resolves to the same IP on both, and pathping returns almost identical traces. 11 of the 13 hops are the same, and then different IPs are answering the request at the remote end.

TMG logging shows request and response on the working node, request only on the non-working node. TMG Connectivity test comes back with "request timed out" but the browser does not, just gets the spinning circle in IE as if awaiting a response (Consistent with what logging shows) Tried clients as SecureNAT and Web Proxy, same results.

Any thoughts, advice etc appreciated as this is a bit of a weird one.
Post #: 1
RE: Facebook.com not working through 1 node of TMG array - 18.Jul.2012 9:15:49 AM   
dvizzle

 

Posts: 236
Joined: 20.Apr.2009
Status: offline
Are they using different servers for DNS?

(in reply to cruachan)
Post #: 2
RE: Facebook.com not working through 1 node of TMG array - 18.Jul.2012 9:58:03 AM   
cruachan

 

Posts: 4
Joined: 18.Jul.2012
Status: offline
No, both TMG nodes use the same 2 internal DNS servers for name resolution.

(in reply to dvizzle)
Post #: 3
RE: Facebook.com not working through 1 node of TMG array - 18.Jul.2012 10:03:58 AM   
dvizzle

 

Posts: 236
Joined: 20.Apr.2009
Status: offline
What does the TMG live logs show for each? Compare them.

Are your rules synchronized across both nodes?

(in reply to cruachan)
Post #: 4
RE: Facebook.com not working through 1 node of TMG array - 18.Jul.2012 10:08:50 AM   
cruachan

 

Posts: 4
Joined: 18.Jul.2012
Status: offline
I take it you mean live monitoring of traffic under Logs & Reports? That's what I was using where I can see the request sent but no reply received for the non-funtional node.

Rules are synchronised, there is a (seperate) EMS Server which reports both nodes in sync and I've checked them manually as well.

(in reply to dvizzle)
Post #: 5
RE: Facebook.com not working through 1 node of TMG array - 27.Aug.2012 4:22:51 AM   
cruachan

 

Posts: 4
Joined: 18.Jul.2012
Status: offline
Sorted it in the end. Even though caching was turned off there was an old cache file on the affected node. Deleting it resolved the issue.

(in reply to cruachan)
Post #: 6

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [Threat Management Gateway (TMG) 2010] >> General >> Facebook.com not working through 1 node of TMG array Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts